package com.stx.test.serialize.evilPackage;

import java.io.ByteArrayInputStream;
import java.io.IOException;
import java.io.ObjectInputStream;

/**
 * packageName com.stx.test.serialize.evilPackage
 *
 * @author YangYi
 * @className execSerialize
 * @date 2025/10/7
 * @description TODO
 */
public class execSerialize {

    public static void receivePack(byte[] data){
        try {
            System.out.println("收到新的包裹");
            ByteArrayInputStream bais = new ByteArrayInputStream(data);
            ObjectInputStream ois = new ObjectInputStream(bais);
            System.out.println("打开包裹");
            ois.readObject();
            System.out.println("结束");
        } catch (Exception e) {
            throw new RuntimeException(e);
        }
    }
}
